Microsoft is accelerating its implementation of passkeys as a more secure alternative to traditional passwords and multifactor authentication (MFA) methods, building on its broader initiative to eliminate passwords for over one billion users amid rising cybersecurity threats.
The technology giant has developed a three-phase approach to implementing passkeys across its ecosystem. The strategy begins with introducing passkey sign-in options at strategic points to familiarize users with the technology. The next phase involves experimental testing to evaluate user acceptance and effectiveness. Finally, Microsoft scales up passkey implementation to make it a default authentication option, a process that will be further enhanced when Microsoft Authenticator adds native passkey support in 2025.
Recent data from Microsoft demonstrates significant advantages of passkey authentication. Users can sign in three times faster with passkeys compared to traditional passwords, and eight times faster than password-plus-MFA combinations. The success rate for passkey authentication stands at 98 percent, considerably higher than the 32 percent success rate for password-based authentication. Additionally, Microsoft reports that 99 percent of users who initiate passkey registration complete the process.
The implementation strategy includes making passkeys unavoidable and incorporating strategic prompts to encourage user enrollment. Microsoft has positioned passkey sign-in as the default option and provides detailed guidance on passkey usage. The effort is supported by recent Windows 11 updates that introduce third-party passkey support, expanding the ecosystem’s compatibility.
A key objective of Microsoft’s passkey initiative is the complete elimination of passwords. The company maintains that accounts remain vulnerable to phishing attempts as long as they retain password-based authentication options. The stance is particularly relevant given the recent surge in sophisticated cyberattacks targeting traditional authentication methods.
The transition comes as traditional MFA systems face security challenges. Recent research demonstrated vulnerabilities in Microsoft Azure MFA, where security researchers successfully bypassed protections by rapidly creating new sessions and systematically testing codes. In response, Microsoft has implemented stricter speed limits and enhanced its adherence to time-based one-time password (TOTP) standards, while simultaneously promoting passkeys as a more robust security solution.
Sources: Biometric Update, Techzine, Intellisuite
Follow Us